Privacy notice
Draft: requires legal review
This notice is a working draft. It has not been reviewed by a lawyer and it is not yet in force. Items in [square brackets] must be confirmed before launch.
The company details are placeholders until they are confirmed.
Draft of
Who is responsible
The controller of your personal data is:
- Company
- SkjoldCyber
- Address
- Denmark
- CVR
- [to be confirmed]
- hello@skanse.example
What we collect
We collect only what is needed to run your case and the service.
- Account data: your name, email address and a password, which is stored only as a one-way hash.
- Intake answers: the type of incident, dates, how contact was made, payment method, amount and currency, recipient details if you know them, what you have reported to your bank or the police, and the free-text account you write.
- Case data: the case reference, status, updates we write to you, and internal notes by case handlers.
- Technical data: a session cookie that keeps you logged in, a language preference, and records of login attempts used to limit abuse [exact fields to be confirmed against the implementation].
Why we use it, and the legal basis
- To provide the service you ask for: creating your account, handling your case and writing to you about it. Basis: contract and steps taken at your request (GDPR Article 6(1)(b)).
- To keep the service secure and prevent abuse. Basis: our legitimate interest (Article 6(1)(f)).
- To meet legal obligations, such as accounting rules. Basis: Article 6(1)(c).
- [Legal review: whether intake answers about being a victim of a criminal offence need an additional basis under the Danish Data Protection Act.]
How long we keep it
[Retention period to be decided, for example a fixed period after a case is completed, with the reason stated.] Data that is no longer needed is deleted.
Who receives it
Our case handlers, and the service providers that host the site and send email on our behalf [providers to be named].
Banks, the police, insurers and Datatilsynet receive information only when your case needs it and you have asked us to share it.
[Transfers outside the EU/EEA: none planned. To be confirmed.]
Your rights
Under the GDPR you have the right to:
- see the data we hold about you, and get a copy;
- have incorrect data corrected;
- have data deleted, where the law allows;
- restrict how we use it, and object to uses based on our legitimate interest;
- receive your data in a portable format;
- withdraw consent, where we rely on it.
Complaints
If you think we handle your data wrongly, tell us first. You also have the right to complain to Datatilsynet (datatilsynet.dk), the Danish Data Protection Agency.
How we protect it
Measures in place in the service:
- Passwords are hashed with a modern one-way algorithm.
- Sessions use HttpOnly cookies and expire.
- Every case can be read only by its owner and by staff, and every staff action on a case is logged.
- Login attempts are rate limited.
- [Encryption in transit and at rest, backups and access control at the hosting provider: to be confirmed at deployment.]
Changes
When this notice changes in a way that matters, we will say so here and, if you have an account, tell you.